Techniques › T1078 › T1078.004
T1078.004 Cloud Accounts
stealth · persistence · privilege escalation · initial access — IaaS, Identity Provider, Office Suite, SaaS · attack.mitre.org · JSON
1
MITRE detection strategy
4
analytics
41
Sigma rules tagged attack.t1078.004
1
KEV CVEs mapped here
<p>Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.</p><p>Service or user accounts may be targeted by adversaries through Brute Force, Phishing, or various other means to gain access to the environment. Federated or synced accounts may be a pathway for the adversary to affect both on-premises systems and cloud environments - for example, by leveraging shared credentials to log onto Remote Services. High privileged cloud accounts, whether federated, synced, or cloud-only, may also allow pivoting to on-premises environments by leveraging SaaS-based Software Deployment Tools to run commands on hybrid-joined devices.</p><p>An adversary may create long lasting Additional Cloud Credentials on a compromised cloud account to maintain persistence in the environment. Such credentials may also be used to bypass security controls such as multi-factor authentication.</p><p>Cloud accounts may also be able to assume Temporary Elevated Cloud Access or other privileges through various means within the environment. Misconfigurations in role assignments or role assumption policies may allow an adversary to use these mechanisms to leverage permissions outside the intended scope of the account. Such over privileged accounts may be used to harvest sensitive data from online storage accounts and databases through Cloud API or other methods. For example, in Azure environments, adversaries may target Azure Managed Identities, which allow associated Azure resources to request access tokens. By compromising a resource with an attached Managed Identity, such as an Azure VM, adversaries may be able to Steal Application Access Tokens to move laterally across the cloud environment.</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
| CVE | Vendor / product | Mapping type | State | Added |
|---|---|---|---|---|
| CVE-2024-53704 | SonicWall SonicOS | primary impact | Mapped | 2025-02-18 |
Detection strategy · ATT&CK Enterprise v19.2
- DET0546 Detection of Abused or Compromised Cloud Accounts for Access and Persistence v1.0
AN1503 Identity ProviderDetects anomalous authentication activity such as sign-ins from impossible geolocations or legacy protocols from high-privileged accounts.Tunable:
AnomalousLocationThresholdProtocolTypeAN1504 IaaSDetects cloud account use for API calls that exceed normal scope, such as IAM changes or access to services never used before.AWS:CloudTrailConsoleLogin, AssumeRole, ListAccessKeys, CreateUser→ DC0002 User Account AuthenticationTunable:ServiceInteractionBaselineRoleSwitchRateThresholdAN1505 SaaSDetects unexpected access or usage of cloud productivity tools (e.g., downloading large numbers of files, creating external shares) by internal users.Tunable:FileDownloadThresholdSharingPolicyViolationThresholdAN1506 Office SuiteDetects login and usage patterns deviating from typical Microsoft 365 or Google Workspace user profiles.Tunable:BusinessHoursOfficeProductivityToolBaseline
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1078.004
Author: Mark Morowczynski '@markmorow', Bailey Bercik '@baileybercik'
· 2022-06-02 · logsource: product=azure service=auditlogs · 0055ad1f-be85-4798-83cf-a6da17c993b3
Detects when a configuration change is made to an applications URI.
URIs for domain names that no longer exist (dangling URIs), not using HTTPS, wildcards at the end of the domain, URIs that are no unique to that app, or URIs that point to domains you do not control should be investigated.
Author: Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H'
· 2022-08-09 · logsource: product=azure service=auditlogs · 039a7469-0296-4450-84c0-f6966b16dc6d
Detects when a PIM elevation is approved or denied. Outside of normal operations should be investigated.
Author: Austin Songer @austinsonger
· 2021-11-26 (modified 2022-08-23) · logsource: product=azure service=activitylogs · 09438caa-07b1-4870-8405-1dbafe3dad95
Detects when a user has been elevated to manage all Azure Subscriptions.
This change should be investigated immediately if it isn't planned.
This setting could allow an attacker access to Azure subscriptions in your environment.
Author: Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H'
· 2022-08-10 · logsource: product=azure service=auditlogs · 0b4b72e3-4c53-4d5b-b198-2c58cfef39a9
Detects when a user that doesn't have permissions to invite a guest user attempts to invite one.
Author: Michael Epping, '@mepples21'
· 2022-06-28 · logsource: product=azure service=auditlogs · 11c767ae-500b-423b-bae3-b234450736ed
Monitor and alert for users added to device admin roles.
Author: Mark Morowczynski '@markmorow', Bailey Bercik '@baileybercik'
· 2022-06-02 · logsource: product=azure service=auditlogs · 1b45b0d1-773f-4f23-aedc-814b759563b1
Detects when a configuration change is made to an applications AppID URI.
Author: MikeDuddington, '@dudders1'
· 2022-07-28 · logsource: product=azure service=signinlogs · 28870ae4-6a13-4616-bd1a-235a7fad7458
Detect failed authentications from countries you do not operate out of.
Author: MikeDuddington, '@dudders1'
· 2022-07-27 · logsource: product=azure service=signinlogs · 28eea407-28d7-4e42-b0be-575d5ba60b2c
Detect when users are authenticating without MFA being required.
Author: Romain Gaillard (@romain-gaillard)
· 2024-07-29 · logsource: product=github service=audit · 2f575940-d85e-4ddc-af13-17dad6f1a0ef
Detects when changes are made to the SSH certificate configuration of the organization.
Author: Ivan Saakov
· 2025-10-19 · logsource: product=aws service=cloudtrail · 313e72de-0c0d-4d65-8c95-87f4d546eceb
Detects AWS console logins from countries and IP addresses that are not recognized as legitimate for the organization.
This alert can help identify potential unauthorized access attempts from unusual locations, which may indicate compromised credentials or malicious activity.
Author: YochanaHenderson, '@Yochana-H'
· 2022-08-03 · logsource: product=azure service=auditlogs · 340ee172-4b67-4fb4-832f-f961bdc1f3aa
Detect when a user has reset their password in Azure AD
Author: Tom Kluter
· 2026-04-28 · logsource: product=gcp service=google_workspace.login · 38360161-76c4-4283-842e-efcf997dafc8
Detects Google Workspace login activity that's classified as suspicious by Google.
Author: Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H'
· 2022-08-06 · logsource: product=azure service=auditlogs · 49a268a4-72f4-4e38-8a7b-885be690c5b5
Detects when a user is added to a privileged role.
Author: Yochana Henderson, '@Yochana-H'
· 2022-06-17 · logsource: product=azure service=signinlogs · 4afac85c-224a-4dd7-b1af-8da40e1c60bd
Detects when an account is disabled or blocked for sign in but tried to log in
Author: Michael Epping, '@mepples21'
· 2022-06-28 (modified 2022-10-05) · logsource: product=azure service=signinlogs · 4d136857-6a1a-432a-82fc-5dd497ee5e7c
Monitor and alert for Sign-ins by unknown devices from non-Trusted locations.
Author: Michael Epping, '@mepples21'
· 2022-06-28 · logsource: product=azure service=signinlogs · 4f77e1d7-3982-4ee0-8489-abf2d6b75284
Monitor and alert for sign-ins where the device was non-compliant.
Author: Harjot Singh, '@cyb3rjy0t'
· 2023-03-20 · logsource: product=azure service=signinlogs · 53bb4f7f-48a8-4475-ac30-5a82ddfdf6fc
Detects successful authentication from potential clients using legacy authentication via user agent strings. This could be a sign of MFA bypass using a password spray attack.
Author: AlertIQ
· 2021-10-10 (modified 2022-12-18) · logsource: product=azure service=signinlogs · 5496ff55-42ec-4369-81cb-00f417029e25
Identifies user login with multifactor authentication failures, which might be an indication an attacker has the password for the account but can't pass the MFA challenge.
Author: Michael Epping, '@mepples21'
· 2022-06-28 · logsource: product=azure service=signinlogs · 5afa454e-030c-4ab4-9253-a90aa7fcc581
Monitor and alert for device registration or join events where MFA was not performed.
Author: MikeDuddington, '@dudders1'
· 2022-06-30 (modified 2026-05-08) · logsource: product=azure service=signinlogs · 5f521e4b-0105-4b72-845b-2198a54487b9
Detect when users in your Azure AD tenant are authenticating to other Azure AD Tenants.
Author: Yochana Henderson, '@Yochana-H'
· 2022-06-17 · logsource: product=azure service=signinlogs · 60f6535a-760f-42a9-be3f-c9a0a025906e
Alert on when legacy authentication has been used on an account
Author: Muhammad Faisal (@faisalusuf)
· 2024-02-25 · logsource: product=bitbucket service=audit · 70ed1d26-0050-4b38-a599-92c53d57d45a
Detects user authentication failure events.
Please note that this rule can be noisy and it is recommended to use with correlation based on "author.name" field.
Author: Thuya@Hacktilizer, Ivan Saakov
· 2025-10-18 (modified 2025-10-21) · logsource: product=aws service=cloudtrail · 77caf516-34e5-4df9-b4db-20744fea0a60
Detects successful AWS console logins that were performed without Multi-Factor Authentication (MFA).
This alert can be used to identify potential unauthorized access attempts, as logging in without MFA can indicate compromised credentials or misconfigured security settings.
Author: vitaliy0x1
· 2020-01-21 (modified 2022-10-09) · logsource: product=aws service=cloudtrail · 8ad1600d-e9dc-4251-b0ee-a65268f29add
Detects AWS root account usage
Author: MikeDuddington, '@dudders1'
· 2022-07-28 (modified 2026-05-08) · logsource: product=azure service=signinlogs · 8c944ecb-6970-4541-8496-be554b8e2846
Detect successful authentications from countries you do not operate out of.
Author: MikeDuddington, '@dudders1'
· 2022-06-30 · logsource: product=azure service=auditlogs · 8dee7a0d-43fd-4b3c-8cd1-605e189d195e
Detects the change of user type from "Guest" to "Member" for potential elevation of privilege.
Author: AlertIQ
· 2021-10-10 (modified 2022-12-25) · logsource: product=azure service=signinlogs · 908655e0-25cf-4ae1-b775-1c8ce9cf43d8
Detect failed attempts to sign in to disabled accounts.
Author: AlertIQ
· 2021-10-10 (modified 2022-12-25) · logsource: product=azure service=signinlogs · 9a60e676-26ac-44c3-814b-0c2a8b977adf
Detect access has been blocked by Conditional Access policies.
The access policy does not allow token issuance which might be sights≈ of unauthorizeed login to valid accounts.
Author: Michael Epping, '@mepples21'
· 2022-06-28 · logsource: product=azure service=auditlogs · a0413867-daf3-43dd-9245-734b3a787942
Monitor and alert for Bitlocker key retrieval.
Author: kelnage
· 2023-09-07 (modified 2026-04-27) · logsource: product=okta service=okta · a0b38b70-3cb5-484b-a4eb-c4d8e7bcc0a9
Detects when Okta identifies new activity in the Admin Console.
Author: Yochana Henderson, '@Yochana-H'
· 2022-06-01 · logsource: product=azure service=signinlogs · b4a6d707-9430-4f5f-af68-0337f52d5c42
Define a baseline threshold for failed sign-ins due to Conditional Access failures
Author: Ivan Saakov
· 2024-12-19 · logsource: product=aws service=cloudtrail · ccd6a6c8-bb4e-4a91-9d2a-07e632819374
Detects the deletion of an AWS SAML provider, potentially indicating malicious intent to disrupt administrative or security team access.
An attacker can remove the SAML provider for the information security team or a team of system administrators, to make it difficult for them to work and investigate at the time of the attack and after it.
Author: daniel.bohannon@permiso.io (@danielhbohannon)
· 2023-05-17 · logsource: product=aws service=cloudtrail · db014773-7375-4f4e-b83b-133337c0ffee
Detects S3 browser utility creating Inline IAM policy containing default S3 bucket name placeholder value of "<YOUR-BUCKET-NAME>".
Author: daniel.bohannon@permiso.io (@danielhbohannon)
· 2023-05-17 · logsource: product=aws service=cloudtrail · db014773-b1d3-46bd-ba26-133337c0ffee
Detects S3 Browser utility performing reconnaissance looking for existing IAM Users without a LoginProfile defined then (when found) creating a LoginProfile.
Author: daniel.bohannon@permiso.io (@danielhbohannon)
· 2023-05-17 · logsource: product=aws service=cloudtrail · db014773-d9d9-4792-91e5-133337c0ffee
Detects S3 Browser utility creating IAM User or AccessKey.
Author: Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H'
· 2022-08-09 · logsource: product=azure service=auditlogs · db6c06c4-bf3b-421c-aa88-15672b88c743
Detects when changes are made to PIM roles
Author: AlertIQ
· 2022-03-24 · logsource: product=azure service=signinlogs · e40f4962-b02b-4192-9bfe-245f7ece1f99
User has indicated they haven't instigated the MFA prompt and could indicate an attacker has the password for the account.
Author: Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H', Tim Shelton
· 2022-08-11 (modified 2022-08-16) · logsource: product=azure service=auditlogs · f7b5b004-dece-46e4-a4a5-f6fd0e1c6947
Detects when a new admin is created.
Author: Muhammad Faisal (@faisalusuf)
· 2023-01-27 · logsource: product=github service=audit · f8ed0e8f-7438-4b79-85eb-f358ef2fbebd
A self-hosted runner is a system that you deploy and manage to execute jobs from GitHub Actions on GitHub.com.
This rule detects changes to self-hosted runners configurations in the environment. The self-hosted runner configuration changes once detected,
it should be validated from GitHub UI because the log entry may not provide full context.
Author: Muhammad Faisal (@faisalusuf)
· 2023-01-20 · logsource: product=github service=audit · f9405037-bc97-4eb7-baba-167dad399b83
Detects when a user creates action secret for the organization, environment, codespaces or repository.
Author: Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H'
· 2022-08-10 · logsource: product=azure service=auditlogs · fa84aaf5-8142-43cd-9ec2-78cfebf878ce
Detects when a temporary access pass (TAP) is added to an account. TAPs added to priv accounts should be investigated
Rules tagged at the parent level (attack.t1078) 56
These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.
Author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'
· 2023-09-03 · logsource: product=azure service=riskdetection · 128faeef-79dd-44ca-b43c-a9e236a60f49
Detects sign-in with properties that are unfamiliar to the user. The detection considers past sign-in history to look for anomalous sign-ins.
Author: Josh Nickels, Marius Rothenbücher
· 2025-01-08 · logsource: product=m365 service=audit · 13f2d3f5-6497-44a7-bf5f-dc13ffafe5dc
Detects a successful login to the Microsoft Intune Company Portal which could allow bypassing Conditional Access Policies and InTune device trust using a tool like TokenSmith.
Author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'
· 2023-09-03 · logsource: product=azure service=riskdetection · 1a41023f-1e70-4026-921a-4d9341a9038e
Identifies two sign-ins originating from geographically distant locations, where at least one of the locations may also be atypical for the user, given past behavior.
Author: Mark Morowczynski '@markmorow', Bailey Bercik '@baileybercik'
· 2022-06-01 · logsource: product=azure service=signinlogs · 248649b7-d64f-46f0-9fb2-a52774166fb5
Device code flow is an OAuth 2.0 protocol flow specifically for input constrained devices and is not used in all environments.
If this type of flow is seen in the environment and not being used in an input constrained device scenario, further investigation is warranted.
This can be a misconfigured application or potentially something malicious.
Author: Micah Babinski (@micahbabinski), Zach Mathis (@yamatosecurity)
· 2023-01-19 (modified 2024-03-11) · logsource: product=windows service=security · 259a9cdf-c4dd-4fa2-b243-2269e5ab18a2
Detects successful logon from public IP address via RDP. This can indicate a publicly-exposed RDP port.
Author: Austin Songer
· 2021-09-06 (modified 2022-06-08) · logsource: product=azure service=auditlogs · 352a54e1-74ba-4929-9d47-8193d67aba1e
Identifies when an user or application modified the federation settings on the domain.
Author: jamesc-grafana
· 2024-07-11 · logsource: product=aws service=cloudtrail · 352a918a-34d8-4882-8470-44830c507aa3
Detects when an instance identity has taken an action that isn't inside SSM.
This can indicate that a compromised EC2 instance is being used as a pivot point.
Author: elhoim
· 2022-09-09 (modified 2023-01-04) · logsource: product=windows service=security · 39698b3f-da92-4bc6-bfb5-645a98386e45
Detects suspicious computer name samtheadmin-{1..100}$ generated by hacktool
Author: Florian Roth (Nextron Systems)
· 2017-03-17 (modified 2023-12-15) · logsource: product=windows service=security · 3ff152b2-1388-4984-9cd9-a323323fdadf
Detects interactive console logons to Server Systems
Author: MikeDuddington, '@dudders1'
· 2022-07-28 (modified 2026-05-09) · logsource: product=azure service=auditlogs · 4ad97bf5-a514-41a4-abd3-4f3455ad4865
Detects guest users being invited to tenant by non-approved inviters
Author: Tim Brown
· 2023-01-09 · logsource: product=cisco service=ldp · 50e606bf-04ce-4ca7-9d54-3449494bbd4b
Detects LDP failures which may be indicative of brute force attacks to manipulate MPLS labels
Author: Security Onion Solutions
· 2024-03-08 · logsource: product=opencanary category=application · 512cff7a-683a-43ad-afe0-dd398e872f36
Detects instances where a Telnet service on an OpenCanary node has had a login attempt.
Author: Mark Morowczynski '@markmorow', Bailey Bercik '@baileybercik'
· 2022-06-01 · logsource: product=azure service=signinlogs · 55695bc0-c8cf-461f-a379-2535f563c854
Resource owner password credentials (ROPC) should be avoided if at all possible as this requires the user to expose their current password credentials to the application directly.
The application then uses those credentials to authenticate the user against the identity provider.
Author: Tim Brown
· 2023-01-09 (modified 2023-01-23) · logsource: product=cisco service=bgp · 56fa3cd6-f8d6-4520-a8c7-607292971886
Detects BGP failures which may be indicative of brute force attacks to manipulate routing
Author: Harjot Singh, '@cyb3rjy0t'
· 2023-01-10 (modified 2025-07-02) · logsource: product=azure service=signinlogs · 572b12d4-9062-11ed-a1eb-0242ac120002
Detects risky authentication from a non AD registered device without MFA being required.
Author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'
· 2023-09-14 · logsource: product=azure service=pim · 58af08eb-f9e1-43c8-9805-3ad9b0482bd8
Identifies when an organization doesn't have the proper license for PIM and is out of compliance.
Author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'
· 2023-09-14 · logsource: product=azure service=pim · 645fd80d-6c07-435b-9e06-7bc1b5656cba
Identifies when the same privilege role has multiple activations by the same user.
Author: Austin Songer @austinsonger
· 2021-11-25 (modified 2022-12-18) · logsource: product=gcp service=gcp.audit · 6ad91e31-53df-4826-bd27-0166171c8040
Identifies when an admission controller is executed in GCP Kubernetes.
A Kubernetes Admission controller intercepts, and possibly modifies, requests to the Kubernetes API server.
The behavior of this admission controller is determined by an admission webhook (MutatingAdmissionWebhook or ValidatingAdmissionWebhook) that the user deploys in the cluster.
An adversary can use such webhooks as the MutatingAdmissionWebhook for obtaining persistence in the cluster.
For example, attackers can intercept and modify the pod creation operations in the cluster and add their malicious container to every created pod. An adversary can use the webhook ValidatingAdmissionWebhook, which could be used to obtain access credentials.
An adversary could use the webhook to intercept the requests to the API server, record secrets, and other sensitive information.
Author: Mark Morowczynski '@markmorow', MikeDuddington, '@dudders1', Tim Shelton
· 2022-08-11 (modified 2022-08-18) · logsource: product=azure service=auditlogs · 6f583da0-3a90-4566-a4ed-83c09fe18bbf
Detects when an account was created and deleted in a short period of time.
Author: Micah Babinski (@micahbabinski), Zach Mathis (@yamatosecurity)
· 2023-01-19 (modified 2024-03-11) · logsource: product=windows service=security · 78d5cab4-557e-454f-9fb9-a222bd0d5edc
Detects successful logon from public IP address via SMB. This can indicate a publicly-exposed SMB port.
Author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'
· 2023-09-14 · logsource: product=azure service=pim · 7bbc309f-e2b1-4eb1-8369-131a367d67d3
Identifies an event where there are there are too many accounts assigned the Global Administrator role.
Author: Sohan G (D4rkCiph3r)
· 2023-08-22 · logsource: product=macos category=process_creation · 821bcf4d-46c7-4b87-bc57-9509d3ba7c11
Detects attempts to enable the root account via "dsenableroot"
Author: Austin Songer @austinsonger
· 2021-11-26 (modified 2022-12-18) · logsource: product=azure service=signinlogs · 8366030e-7216-476b-9927-271d79f13cf3
Detects when there is a interruption in the authentication process.
Author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'
· 2023-09-14 · logsource: product=azure service=pim · 8c6ec464-4ae4-43ac-936a-291da66ed13d
Identifies when a user has been assigned a privilege role and are not using that role.
Author: Ivan Saakov
· 2024-12-19 · logsource: product=aws service=cloudtrail · 92f84194-8d9a-4ee0-8699-c30bfac59780
Detects the import of SSH key pairs into AWS EC2, which may indicate an attacker attempting to gain unauthorized access to instances. This activity could lead to initial access, persistence, or privilege escalation, potentially compromising sensitive data and operations.
Author: oscd.community, Teymur Kheirkhabarov @HeirhabarovT, Zach Stanford @svch0st, Tim Shelton
· 2020-10-05 (modified 2022-08-03) · logsource: product=windows service=security · 941e5c45-cda7-4864-8cea-bbb7458d194a
Detects suspicious processes logging on with explicit credentials
Author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'
· 2023-09-03 · logsource: product=azure service=riskdetection · 944f6adb-7a99-4c69-80c1-b712579e93e6
Indicates anomalous behavior based on suspicious sign-in activity across multiple tenants from different countries in the same browser
Author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'
· 2023-09-14 · logsource: product=azure service=pim · 94a66f46-5b64-46ce-80b2-75dcbe627cc0
Identifies when a privilege role can be activated without performing mfa.
Author: Florian Roth (Nextron Systems)
· 2017-02-19 (modified 2025-10-17) · logsource: product=windows service=security · 9eb99343-d336-4020-a3cd-67f3819e68ee
This method uses uncommon error codes on failed logons to determine suspicious activity and tampering with accounts that have been disabled or somehow restricted.
Author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'
· 2023-09-07 · logsource: product=azure service=riskdetection · a2cb56ff-4f46-437a-a0fa-ffa4d1303cba
Indicates user activity that is unusual for the user or consistent with known attack patterns.
Author: Tim Brown
· 2023-01-09 (modified 2023-01-23) · logsource: product=huawei service=bgp · a557ffe6-ac54-43d2-ae69-158027082350
Detects BGP failures which may be indicative of brute force attacks to manipulate routing.
Author: Austin Songer @austinsonger
· 2021-11-25 (modified 2022-12-18) · logsource: product=azure service=activitylogs · a61a3c56-4ce2-4351-a079-88ae4cbd2b58
Identifies when an admission controller is executed in Azure Kubernetes.
A Kubernetes Admission controller intercepts, and possibly modifies, requests to the Kubernetes API server.
The behavior of this admission controller is determined by an admission webhook (MutatingAdmissionWebhook or ValidatingAdmissionWebhook) that the user deploys in the cluster.
An adversary can use such webhooks as the MutatingAdmissionWebhook for obtaining persistence in the cluster.
For example, attackers can intercept and modify the pod creation operations in the cluster and add their malicious container to every created pod.
An adversary can use the webhook ValidatingAdmissionWebhook, which could be used to obtain access credentials.
An adversary could use the webhook to intercept the requests to the API server, record secrets, and other sensitive information.
Author: Tim Brown
· 2023-01-09 (modified 2023-01-23) · logsource: product=juniper service=bgp · a7c0ae48-8df8-42bf-91bd-2ea57e2f9d43
Detects juniper BGP missing MD5 digest. Which may be indicative of brute force attacks to manipulate routing.
Author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'
· 2023-09-03 · logsource: product=azure service=riskdetection · adf9f4d2-559e-4f5c-95be-c28dff0b1476
Detects sign-ins from new countries. The detection considers past activity locations to determine new and infrequent locations.
Author: Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H'
· 2022-08-09 · logsource: product=azure service=auditlogs · aeaef14c-e5bf-4690-a9c8-835caad458bd
Detects when PIM alerts are set to disabled.
Author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'
· 2023-09-14 · logsource: product=azure service=pim · b1bc08d1-8224-4758-a0e6-fbcfc98c73bb
Identifies when a privilege role assignment has taken place outside of PIM and may indicate an attack.
Author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'
· 2023-09-03 · logsource: product=azure service=riskdetection · b2572bf9-e20a-4594-b528-40bde666525a
Identifies user activities originating from geographically distant locations within a time period shorter than the time it takes to travel from the first location to the second.
Author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'
· 2023-09-03 · logsource: product=azure service=riskdetection · be4d9c86-d702-4030-b52e-c7859110e5e8
Identifies that users were active from an IP address that has been identified as an anonymous proxy IP address.
Author: Austin Songer @austinsonger
· 2021-08-23 (modified 2022-10-09) · logsource: product=m365 service=threat_management · c191e2fa-f9d6-4ccf-82af-4f2aba08359f
Detects when a Microsoft Cloud App Security reported when a user signs into your sanctioned apps from a risky IP address.
Author: Florian Roth (Nextron Systems)
· 2017-03-14 (modified 2021-01-17) · logsource: product=windows service=security · c265cf08-3f99-46c1-8d59-328247057d57
Detects the addition of a new member to the local administrator group, which could be legitimate activity or a sign of privilege escalation activity
Author: Mark Morowczynski '@markmorow', MikeDuddington, '@dudders1'
· 2022-08-11 (modified 2023-12-15) · logsource: product=azure service=auditlogs · c98184ba-4a27-4e10-b7b7-da48e71f4d25
Detects accounts that are created or deleted by non-approved users.
Author: Austin Songer @austinsonger
· 2021-11-26 (modified 2022-12-25) · logsource: product=azure service=auditlogs · ca9bf243-465e-494a-9e54-bf9fc239057d
Detects when a user has been elevated to manage all Azure Subscriptions.
This change should be investigated immediately if it isn't planned.
This setting could allow an attacker access to Azure subscriptions in your environment.
Author: Security Onion Solutions
· 2024-03-08 · logsource: product=opencanary category=application · cd55f721-5623-4663-bd9b-5229cab5237d
Detects instances where an SSH service on an OpenCanary node has had a connection attempt.
Author: Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H'
· 2022-08-11 (modified 2023-12-15) · logsource: product=azure service=signinlogs · cf1e5687-84e1-41af-97a9-158094efef53
Detects failed sign-in due to user not meeting expected controls for adminitrators
Author: Tim Shelton (HAWK.IO)
· 2021-12-09 (modified 2023-02-21) · logsource: product=windows category=process_creation · d4498716-1d52-438f-8084-4a603157d131
Detects a when net.exe is called with a password in the command line
Author: Sohan G (D4rkCiph3r)
· 2023-02-18 · logsource: product=macos category=process_creation · d7329412-13bd-44ba-a072-3387f804a106
Detects attempts to enable the guest account using the sysadminctl utility
Author: Austin Songer @austinsonger
· 2020-07-06 (modified 2021-11-27) · logsource: product=m365 service=threat_management · d7eab125-5f94-43df-8710-795b80fa1189
Detects when a Microsoft Cloud App Security reported a risky sign-in attempt due to a login associated with an impossible travel.
Author: frack113
· 2022-02-21 · logsource: product=windows category=ps_module · e3818659-5016-4811-a73c-dde4679169d2
The Reset-ComputerMachinePassword cmdlet changes the computer account password that the computers use to authenticate to the domain controllers in the domain.
You can use it to reset the password of the local computer.
Author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'
· 2023-09-14 · logsource: product=azure service=pim · e402c26a-267a-45bd-9615-bd9ceda6da85
Identifies when an account hasn't signed in during the past n number of days.
Author: Tom Kluter
· 2026-04-28 · logsource: product=gcp service=google_workspace.login · eafe6f2b-cfec-4612-aec2-49563c33a087
Detects a login attempt in Google Workspace flagged as a potential attack by a government-backed threat actor
Author: Raphaël CALVET, @MetallicHack
· 2021-10-04 (modified 2026-04-30) · logsource: product=azure service=auditlogs · ebbeb024-5b1d-4e16-9c0c-917f86c708a7
User Added to an Administrator's Azure AD Role
Author: kelnage
· 2024-07-11 · logsource: product=kubernetes service=audit · eed82177-38f5-4299-8a76-098d50d225ab
Detects when a modification (create, update or replace) action is taken that affects mutating or validating webhook configurations, as they can be used by an adversary to achieve persistence or exfiltrate access credentials.
Author: MikeDuddington, '@dudders1'
· 2022-07-28 (modified 2026-05-08) · logsource: product=azure service=signinlogs · f272fb46-25f2-422c-b667-45837994980f
Detect when authentications to important application(s) only required single-factor authentication
Author: Austin Songer
· 2021-09-22 (modified 2022-12-18) · logsource: product=aws service=cloudtrail · f43f5d2f-3f2a-4cc8-b1af-81fde7dbaf0e
Identifies when suspicious SAML activity has occurred in AWS. An adversary could gain backdoor access via SAML.
Author: NVISO
· 2020-05-06 (modified 2024-03-11) · logsource: product=windows service=security · f88e112a-21aa-44bd-9b01-6ee2a2bbbed1
Detects a failed logon attempt from a public IP. A login from a public IP can indicate a misconfigured firewall or network boundary.
Author: Security Onion Solutions
· 2024-03-08 · logsource: product=opencanary category=application · ff7139bc-fdb1-4437-92f2-6afefe8884cb
Detects instances where an SSH service on an OpenCanary node has had a login attempt.